Resetting WinCC RT Advanced Password and Direct Ethernet Download

David Krause13 min read
SiemensTechnical ReferenceTIA Portal
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Overview: PC-Based HMI vs. Panel HMI in TIA Portal

Siemens SIMATIC HMI deployments split into two architectural families: panel-based HMIs (KTP, TP, MP, Comfort, Unified Comfort Panels) and PC-based HMIs running on industrial PCs under WinCC Runtime Advanced or WinCC Runtime Professional. In TIA Portal V13 (and later V15, V16, V17, V18, V19), these two device classes are represented by fundamentally different device objects in the project tree, and each carries its own runtime, configuration, and security envelope.

On a panel HMI, the project compiles to a single HMI image that is downloaded directly to the panel over Ethernet, PROFINET, USB, MPI, or PROFIBUS. The target operating system, file system, and runtime are embedded in the panel firmware.

On a PC-based HMI, the project compiles to a .fwc / .zip runtime package that is loaded onto a Windows-based IPC (e.g., SIMATIC IPC227G, IPC627, IPC847, or any compatible x86 machine). The runtime is delivered as a Windows service plus configuration. The engineering side requires an extra SIMATIC PC station device in the project tree, which in turn contains an HMI_RT_1 application slot. That is the entry you will not see on a normal panel HMI project — the right-hand device in a typical project shows only the panel itself with its integrated runtime components.

Architectural Differences in the Project Tree

Open a project in TIA Portal that contains both device types and compare the project tree nodes:

Project Tree Item PC Station (WinCC RT Advanced) Panel HMI (e.g., TP1200 Comfort)
Top-level device SIMATIC PC station HMI_1 / TP1200 Comfort
HMI_RT application slot Present (HMI_RT_1) Not present (runtime is part of device)
WinCC RT Advanced / Professional entry Under PC station → HMI_RT_1 Direct under device → Screens / Tags / Alarms
Runtime loader RT Loader (SmrtRT.exe) as Windows autostart Built into panel firmware; no separate loader
OS dependency Windows 7 / 10 / 11 LTSC, Windows Server Siemens-licensed embedded firmware
User administration storage Windows registry + project file (encrypted) Internal Flash of the panel

The HMI_RT_1 slot is the binding point between the PC station hardware (IPC, network cards, OPC slots) and the WinCC Runtime Advanced configuration. Without it, the compiled runtime has no host process to attach to.

Why a Password Aging Lockout Matters

WinCC Runtime Advanced supports a user administration system that can enforce password aging (the project property User administration → Password aging in days). When the configured lifetime expires, the runtime blocks login for the affected user until an administrator resets the credentials, or — depending on project settings — the user is forced to change the password at next login.

Security design intent: Password aging on a production HMI is meant to prevent indefinite use of a compromised credential. However, on a long-running PC station it commonly causes a hard lockout when the original administrator account is forgotten. This is the most frequent cause of "we no longer know the password" escalations on shop-floor IPCs.

Symptoms of a password-aging lockout on a PC station:

  • The WinCC Runtime login dialog rejects every known user with User name or password invalid or Password has expired.
  • Project transfer via TIA Portal still prompts for a transfer password; if the engineering transfer password is also unknown, the runtime cannot be overwritten cleanly from the engineering station.
  • The Runtime → User view on the operator screen is grayed out, and the User administration dialog inside Runtime requires admin credentials to open.

Does an Unknown Runtime Password Block a Download?

This is the most important practical question, and the answer depends on the configured transfer password (not the runtime user password).

There are two distinct passwords in play on a WinCC Runtime Advanced PC station:

Password Scope Default / Reset
Runtime user password (UMAC) Controls login to operator screens and user management inside the running HMI Stored in the encrypted project file; recoverable only by editing the project, or by an existing administrator resetting the user from the running runtime
Transfer password Controls project download from TIA Portal to the target (over Ethernet / USB / RT Loader) Defined in HMI device → Runtime settings → Transfer; required to overwrite the project on the target

With the transfer password known, you can always overwrite the project, which replaces the user administration with a fresh set of credentials from the new compile. A forgotten runtime user password, by itself, does not prevent a TIA Portal download — but a forgotten transfer password does, because TIA Portal authenticates the download against that value.

Default transfer password: "0000" was common in WinCC flexible 2008 and early TIA Portal projects. In V13 SP1 and later, Siemens enforces a user-defined transfer password at compile time if the project option Use default transfer password is disabled. Confirm with the project engineer before assuming the default.

Recovering the Runtime User Password on a PC Station

On a panel HMI, the most common recovery is a factory reset (described below). On a PC station running WinCC Runtime Advanced, the recovery surface is wider because the runtime sits on top of Windows.

Option A — Re-download the project from TIA Portal

  1. Open the original TIA Portal V13 (or migrated V15/V16/V17) project.
  2. Navigate to HMI_RT_1 → User administration and reset the admin password to a known value, or recreate the user list with a fresh administrator.
  3. Compile the project (Project → Compile → Software (rebuild all)).
  4. Transfer the project to the PC station using the procedure in the next section.

This is the cleanest path because it also clears any pending password-aging timer.

Option B — Edit the project file directly (advanced)

The runtime user database is embedded in the compiled *.fwc / *.zip package. In TIA Portal you can re-open the source *.ap13 (or *.ap14 ... *.ap19) project, change the passwords under User administration, and recompile. The protected store on the PC is overwritten on next transfer.

Option C — Operate Runtime to reset the password

If a second administrator (non-expired) account still exists and is logged into the runtime, that administrator can open User view → Change password for the locked account. This is rarely available on aged production systems, but it is the fastest path when it is.

Option D — Last-resort Windows-level reset (engineering decision)

Because the runtime is a Windows service, a controlled reset is possible by:

  1. Stopping the WinCC Runtime service (SmartRT.exe / CCRT.exe) on the IPC.
  2. Removing or renaming the encrypted user store file (location depends on the runtime version; typical path C:\Program Files\Siemens\Automation\WinCC RT Advanced\ or the project folder).
  3. Restarting the runtime, which will fall back to a default user list and require re-import of the engineered user administration.
Do not delete the entire project folder. The runtime project file contains screens, tag connections, alarm logs, and recipe data that are not in the engineering source archive. Always back up C:\ProgramData\Siemens\Automation\WinCC RT Advanced and the project directory before any Windows-level reset.

Connecting TIA Portal Directly to a PC Station over Ethernet

Direct download from a programming PC to a WinCC Runtime Advanced PC station over Ethernet is fully supported and is the standard commissioning path. Configure the link as follows.

Prerequisites

  • TIA Portal V13 SP1 or later installed on the engineering station (the same major version family as the project).
  • WinCC Runtime Advanced installed on the target IPC, version compatible with the TIA Portal version used to compile the project (e.g., TIA V16 ↔ WinCC RT Advanced V16).
  • Ethernet connectivity: same subnet, ping verified, no managed-switch ACL blocking TCP/UDP ports used by TIA transfer (TCP 102 for S7ONLINE, additional ports 2308, 50523, 6280 etc. depending on the runtime).
  • Administrator rights on the target IPC (required to install and start RT Loader).
  • Known transfer password (or default 0000 if the project still has the default enabled).

Step-by-Step: Direct Ethernet Transfer to a PC Station

  1. Configure the PG/PC interface on the engineering station. Open Control Panel → Set PG/PC Interface and select S7ONLINE (STEP7) → TCP/IP → <your NIC>. This routes the download through the standard S7 communication path used by TIA Portal.
  2. Verify the target IPC network settings. The IPC must have a static IP in the same subnet, or use DHCP reserved by MAC. The RT Loader window on the IPC displays the device's IP under Settings → Network.
  3. Open the project in TIA Portal and select the HMI_RT_1 device. Right-click → Download to device → Software (all). If prompted, accept the certificate of the target runtime.
  4. Select the target PG/PC interface. In the Download to device dialog, choose PN/IE as the type of interface and the NIC that matches the subnet of the IPC.
  5. Search for and select the target. Click Search. The IPC appears by its IP and (if configured) PROFINET device name. Highlight it and confirm.
  6. Enter the transfer password. Type the configured transfer password; if the project was compiled with the default and the runtime was never changed, 0000 works. With the correct transfer password, TIA Portal can overwrite the existing project — including replacing the user administration with the new one.
  7. Confirm overwrite. Acknowledge the prompt that the existing project will be overwritten. The runtime is stopped, the new project is transferred, and the runtime restarts automatically.
  8. Verify login. When the runtime reopens, log in with the freshly compiled administrator credentials and confirm that user administration → password aging is set to a workable value (e.g., 90 days) or disabled until after commissioning.

Using RT Loader for Indirect Transfer

If the target IPC is not on the same network as the engineering station, or if the runtime is unreachable because of an authentication failure, Siemens provides RT Loader as a Windows-side tool to install and start the runtime from a package file. This is the alternative to direct Ethernet download.

  1. Compile the HMI project in TIA Portal to a *.fwc runtime file (target → Compile → Software (rebuild all)).
  2. Copy the *.fwc to a USB stick or shared network folder.
  3. On the IPC, start RT Loader from the Windows start menu or C:\Program Files\Siemens\Automation\WinCC RT Advanced\RTLoader.exe.
  4. In RT Loader → Settings → Path, browse to the *.fwc.
  5. Enable Autostart so the runtime restarts automatically after a reboot.
  6. Click Start Runtime. The IPC boots into the new HMI project with the freshly compiled user administration.

This path bypasses the transfer password entirely because the new project file is loaded from local media. It is the recommended recovery route when both the runtime user password and the transfer password are unknown.

Factory Reset of a Panel HMI (For Comparison)

On a panel HMI (Comfort / Unified), a forgotten password is normally recovered through the panel's service menu:

  1. Power off the panel.
  2. Hold the appropriate service button while powering on (varies by model — for TP/Comfort panels, the recessed button on the back or the touch hold on a corner during boot).
  3. Select Boot → Reset to factory settings from the recovery menu.
  4. Confirm the warning. The panel's internal flash is wiped, all users and the project are removed, and the panel returns to a clean commissioning state ready for a fresh download.

This option exists only on panel HMIs. PC stations do not have a hardware service menu — the equivalent is reinstalling the runtime and re-transferring the project.

Hardening the Project After Recovery

After a successful recovery, take the opportunity to harden the configuration so the situation does not recur.

Setting Recommended Value Reason
Password aging Disabled (or 90+ days) on commissioning projects Prevents accidental lockout on long-running HMIs
Transfer password Custom, stored in a password vault Default 0000 is a security exposure on production
Number of administrators At least 2 with distinct credentials Redundancy if one account is compromised
User administration export Encrypted backup in the project archive Enables offline credential recovery
RT Loader autostart Enabled, with a known *.fwc path Faster recovery via USB on network loss

Troubleshooting Matrix

Symptom Likely Cause Action
Login rejected on IPC runtime Password aging expired Re-transfer the project from TIA Portal, or use RT Loader to load a fresh *.fwc
"Transfer password incorrect" in TIA Portal Default 0000 was changed at compile time Recover the password from project documentation, or bypass via RT Loader
PC station not visible in TIA search Wrong subnet or firewall on Windows Set Windows Defender Firewall inbound rule to allow Siemens applications, verify ping, check PROFINET name resolution
RT Loader not present on IPC Runtime not installed, or older version Reinstall WinCC Runtime Advanced matching the TIA Portal major version
Project compiles but runtime shows "Project corrupt" Version mismatch between TIA compile and installed runtime Match versions (TIA V16 ↔ RT Advanced V16); see Siemens compatibility list
HMI_RT_1 missing from project tree Wrong device class selected — a panel device was added instead of a PC station Delete the panel, add SIMATIC PC station → HMI RT Advanced from the device catalog

Field-Proven Caveats

  • Version coupling. A TIA Portal V13 project can be transferred to a runtime that supports it, but upgrading a long-running V13 PC station to V16/V17 is a major undertaking: backup, uninstall runtime, install new runtime, recompile, redeploy. Plan for downtime.
  • PROFINET names. PC stations and panels that talk to S7-1500 / S7-1200 controllers are typically addressed by PROFINET device name in the project, not only by IP. If the IPC has been renamed in Windows or replaced, the PROFINET name must be reassigned through RT Loader → Settings → Station Configuration before the controller will exchange data with it.
  • Antivirus interference. Some enterprise antivirus suites quarantine SmartRT.exe or block the TIA transfer ports. Add the Siemens runtime directory to the AV exclusion list during commissioning.
  • UAC and standard user. On Windows 10/11, the runtime service must run under an account that can read the project folder and write to its log directory. Using a domain service account with a non-expiring password is a common production pattern.

Quick Reference: Connection Path Decision

TIA Portal → PC Station Recovery Password lockout on PC station Transfer password known? Transfer password unknown? Direct Ethernet download via TIA Portal Compile *.fwc → USB → RT Loader on IPC Runtime restarts with new user administration

FAQ

What is the difference between HMI_RT_1 and a normal HMI device in TIA Portal?

HMI_RT_1 is the runtime application slot inside a SIMATIC PC station that hosts WinCC Runtime Advanced or Professional. A normal HMI device (KTP, TP, MP, Comfort, Unified Panel) is a single integrated device that contains its own runtime. HMI_RT_1 is only present in PC-based HMI projects; see the official TIA Portal HMI connection configuration documentation for how the slots map to the runtime services.

Can I download a project to a PC station without knowing the runtime user password?

Yes, in most cases. The runtime user password (UMAC) controls operator login inside the running HMI. The download from TIA Portal is gated by the separate transfer password, not the runtime user password. With the transfer password known, you can overwrite the project and replace the user administration with a fresh set of credentials.

How do I recover a PC station if both the runtime and transfer passwords are lost?

Compile the HMI project to a *.fwc runtime file in TIA Portal, copy it to USB, and use RT Loader on the IPC to start the new project from local media. This bypasses the transfer password entirely and is the recommended last-resort path documented in the Siemens TIA Portal help portal.

Does TIA Portal V13 support direct Ethernet download to a PC station?

Yes. Configure the PG/PC interface to S7ONLINE → TCP/IP → <NIC> on the engineering station, ensure the IPC is on the same subnet, right-click the HMI_RT_1 device, choose Download to device → Software (all), and search for the target. Enter the transfer password when prompted.

Is WinCC Runtime Advanced the same as WinCC Unified?

No. WinCC Runtime Advanced is the Windows-based runtime for SIMATIC Panels and PC stations engineered in TIA Portal. WinCC Unified is a separate, web-based runtime family used with Unified Comfort Panels and Unified PC systems. Migration paths and tooling differ; for new projects on modern hardware, review the SIMATIC WinCC Unified Engineering portfolio before deciding which runtime family to standardize on.

Back to blog